You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel 5.6如何排除文件夹并实现路由身份验证?

Fixing Authenticated Access to Your Game Files in Laravel 5.6

Got it, let's break down the problem first: Your web server (Apache/Nginx) prioritizes the physical public/uploads folder over Laravel's routes. When someone requests /uploads, the server serves the folder directly instead of passing the request to Laravel—this is why your route isn't firing. Here's how to fix this while ensuring only authenticated users can access the game files:

Step 1: Move Game Files Out of Public for Security

First, we need to block direct public access to the game files. Move the public/uploads/games folder to storage/app/games. The storage directory isn't web-accessible by default, so this forces all requests to go through Laravel's routing layer where we can add authentication checks.

Step 2: Create a Protected Route

Update your routes/web.php to add a route that handles game file requests, with the auth middleware to restrict access to logged-in users:

Route::get('/games/{path}', function ($path) {
    // Build the full path to the requested file
    $filePath = storage_path('app/games/' . $path);

    // Critical security check: Block directory traversal attacks
    $realFile = realpath($filePath);
    $baseGameDir = realpath(storage_path('app/games'));
    
    if (!$realFile || strpos($realFile, $baseGameDir) !== 0) {
        abort(403, 'Unauthorized access to file');
    }

    // Check if the file actually exists
    if (!file_exists($realFile)) {
        abort(404);
    }

    // Get the correct MIME type for proper browser rendering
    $mime = mime_content_type($realFile);

    // Return the file with appropriate headers
    return response()->file($realFile, ['Content-Type' => $mime]);
})->middleware('auth')->where('path', '.*');

What this route does:

  • The {path} parameter captures all subdirectories and files (e.g., css/style.css or js/game.js)
  • The auth middleware ensures only logged-in users can reach this route
  • We add security checks to prevent users from accessing sensitive files (like .env) via directory traversal
  • Finally, we return the file with the correct MIME type so browsers render CSS/JS/HTML properly

Step 3: Update Resource Paths in the Game's HTML

Open the game's main HTML file and update all resource paths to point to the new /games route. For example:

  • Change <link rel="stylesheet" href="css/style.css"> to <link rel="stylesheet" href="/games/css/style.css">
  • Change <script src="js/game.js"></script> to <script src="/games/js/game.js"></script>

Alternative: Adjust Web Server Configuration (Less Secure)

If you absolutely can't move the files out of public/uploads, you can tweak your web server config to force /uploads requests through Laravel first. This is riskier if misconfigured, but here's how:

For Nginx:

Add a specific location block for /uploads before your general / block:

server {
    # ... other existing config ...

    location /uploads {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }
}

For Apache:

Update your public/.htaccess file to modify rewrite rules:

RewriteEngine On

# Force /uploads requests through Laravel
RewriteRule ^uploads/(.*)$ index.php?$1 [L]

# ... rest of your existing rewrite rules ...

Then you can use a route like Route::get('/uploads/games/{path}', ...)->middleware('auth'), but moving files to storage is the safer, more maintainable approach.

Final Checks

  • Test accessing /games while logged out: You should be redirected to the login page
  • Test accessing a specific file (e.g., /games/css/style.css) while logged in: It should load correctly
  • Verify direct access to storage/app/games isn't possible (it shouldn't be, since storage isn't web-accessible)

内容的提问来源于stack exchange,提问作者Anik Sen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:29:25